dev-testing-frontend
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- External Downloads & Remote Code Execution: The skill utilizes
npxto fetch and execute documentation and analysis tools from the@sveltejsorganization. This is a common method for utilizing modern development utilities from established software maintainers. - Command Execution: The instructions involve standard shell commands for development workflows, including
pnpm,vitest, andjust. These operations are expected within the scope of a software testing and build pipeline. - Indirect Prompt Injection Surface: The
svelte-autofixertool processes external code strings or file paths as input, which creates a surface for potential indirect prompt injection. This risk is inherent to the tool's intended purpose of analyzing and suggesting fixes for code. (1) Ingestion points: The<code_or_path>argument in thesvelte-autofixerCLI command withinreferences/svelte5.mdaccepts external content. (2) Boundary markers: The instructions recommend escaping shell-sensitive characters like$, but do not specify internal prompt delimiters for the model. (3) Capability inventory: The skill has the capability to execute shell commands for testing, building, and documentation retrieval. (4) Sanitization: Manual escaping of characters is recommended in the guidelines to prevent unintended shell substitution.
Audit Metadata